Skip to content

Structural analysis

Structural analysis: capturing the information domain without getting lost in the inventory

Business processes first, technology second. That keeps visible which information and systems actually matter for the service.

Back to BSI IT-Grundschutz

9 minute read · Content as of 21.07.2026

The structural analysis maps dependencies

It records business processes, information, applications, IT systems, communication links and rooms. The order matters: technology is considered in the context of the service it supports.

An existing CMDB or asset inventory can supply data, but it does not automatically replace the business-side assignment or the granularity IT-Grundschutz requires.

Grouping keeps the model manageable

Similar target objects may sensibly be grouped when their type of use, configuration and protection needs are sufficiently comparable. Groups that are too coarse hide differences; groups that are too fine make upkeep and modelling needlessly expensive.

  • Unique IDs and object owners
  • Link to processes and information
  • Location and technical dependencies
  • Documented grouping criteria
  • Review on significant changes

The free CSV starter creates a shared structure

The template connects object classes, responsibilities, dependencies and data provenance. It is deliberately lean enough for the first workshop and open to a later tool import.

Sources used

  • BSI Standard 200-2 · BSI · Version 1.0 · October 2017
  • Grundschutz practice patterns · KaitoSec

Back to BSI IT-Grundschutz